Vulnerability record · CVE-2020-3569 · published 23 September 2020
CVE-2020-3569: Cisco IOS XR DVMRP IGMP packet handling memory exhaustion
Cisco · Ios Xr
Cisco IOS XR Software mishandles IGMP packets in its Distance Vector Multicast Routing Protocol (DVMRP) feature, allowing crafted traffic to crash the IGMP process or exhaust device memory. Because the affected process can drag down other processes such as interior and exterior routing protocols, a single remote packet stream can destabilize routing on the device.
Description
Multiple vulnerabilities in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to either immediately crash the Internet Group Management Protocol (IGMP) process or make it consume available memory and eventually crash. The memory consumption may negatively impact other processes that are running on the device. These vulnerabilities are due to the incorrect handling of IGMP packets. An attacker could exploit these vulnerabilities by sending crafted IGMP traffic to an affected device. A successful exploit could allow the attacker to immediately crash the IGMP process or cause memory exhaustion, resulting in other processes becoming unstable. These processes may include, but are not limited to, interior and exterior routing protocols. Cisco will release software updates that address these vulnerabilities.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Automated analysis
high priorityRemote, unauthenticated denial of service with CISA KEV exploitation evidence and a CVSS base of 8.6, though impact is availability-only and EPSS probability is modest.
What it is
Cisco IOS XR Software mishandles IGMP packets in its Distance Vector Multicast Routing Protocol (DVMRP) feature, allowing crafted traffic to crash the IGMP process or exhaust device memory. Because the affected process can drag down other processes such as interior and exterior routing protocols, a single remote packet stream can destabilize routing on the device.
Impact
An unauthenticated remote attacker can immediately crash the IGMP process or drive memory exhaustion that makes other processes, including routing protocols, unstable. The result is denial of service on the affected device rather than code execution or data exposure.
Attack surface
Reachable over the network by sending crafted IGMP traffic to an affected device; the CVSS vector shows no privileges and no user interaction required. DVMRP must be relevant to the device's configuration for the vulnerable code path to be exercised.
Exploitation
CVE-2020-3569 is listed in CISA's Known Exploited Vulnerabilities catalog with a 2021-11-03 addition date, indicating exploitation in the wild; EPSS gives a 30-day probability of about 3.3 percent (88th percentile). No ransomware campaign use is documented.
What to do
- Apply the Cisco IOS XR software updates referenced in the vendor advisory cisco-sa-iosxr-dvmrp-memexh-dSmpdvfz.
- If DVMRP is not required, disable the DVMRP feature to remove the vulnerable code path.
- Restrict IGMP and multicast traffic to trusted network segments using infrastructure ACLs and multicast boundary controls.
- Monitor device memory and process health for the IGMP process and routing protocol processes to catch early exhaustion.
- Track CISA KEV remediation due date (2022-05-03) and confirm patched status across the fleet.
Detection
- Alert on IGMP process crashes or restarts in IOS XR logs and syslog.
- Monitor device memory utilization trends for unexplained growth correlated with multicast traffic.
- Watch for routing protocol process instability or adjacency flaps following multicast traffic bursts.
- Baseline and inspect inbound IGMP traffic volumes and sources at network edges for anomalies.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2020-3569 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxr-dvmrp-memexh-dSmpdvfz | MitigationVendor Advisory |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxr-dvmrp-memexh-dSmpdvfz | MitigationVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-3569 | US Government Resource |
Track CVE-2020-3569 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-3569), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.